Weaknesses of type CWE-522

689 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2023-50125MEDIUMA default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm system to a disarmed stEPSS 0.4%CVE-2026-75015MEDIUMApache Syncope: Nested secrets leak cleartext into audit records readableEPSS 0.4%CVE-2026-20234CRITICALCisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential VulnerabilitiesEPSS 0.4%CVE-2025-0477CRITICALRockwell Automation FactoryTalk® AssetCentre Data Exposure VulnerabilityEPSS 0.4%CVE-2024-39290MEDIUMInsufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtaiEPSS 0.4%CVE-2026-55553HIGHurllib: Cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakageEPSS 0.4%CVE-2024-33849MEDIUMci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.EPSS 0.4%CVE-2026-71494MEDIUMInfracost: Terraform Cloud and registry token disclosure via unvalidated hostnameEPSS 0.4%CVE-2026-55180MEDIUMpnpm: Repository config can expand victim environment secrets into registry requests before scripts runEPSS 0.4%CVE-2023-29447MEDIUMInsufficiently Protected Credentials in PTC's Kepware KEPServerEXEPSS 0.4%CVE-2025-53654MEDIUMJenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins cEPSS 0.4%CVE-2024-38291HIGHIn XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.EPSS 0.4%CVE-2023-4538MEDIUMShared Key in Comarch ERP XLEPSS 0.4%CVE-2025-54380MEDIUMOpencast still publishes global system account credentialsEPSS 0.4%CVE-2024-29071HIGHHGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change thEPSS 0.4%CVE-2026-67427HIGHFlyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylistedEPSS 0.4%CVE-2020-7299MEDIUMSensitive Data Exposure vulnerability in McAfee True Key Windows ClientEPSS 0.4%CVE-2022-34311MEDIUMIBM CICS TX session fixationEPSS 0.4%CVE-2026-20359CRITICALCisco Crosswork Security Hardening Release: August 2026EPSS 0.4%CVE-2026-46458HIGHCredential exposure in ICU Scandinavia BoomerangEPSS 0.4%